Spotlight On: Insider Threat from Trusted Business Partners Version 2: Updated and Revised

SEI Report
In this article, the authors focus on cases in which the malicious insider was employed by a trusted business partner of the victim organization.
Publisher

Software Engineering Institute

Topic or Tag

Abstract

This article is the sixth in the series Spotlight On, published by the CERT® Insider Threat Center at Carnegie Mellon University's Software Engineering Institute and funded by CyLab. Each article focuses on a specific area of concern and presents analysis based on hundreds of actual insider threat cases cataloged in the CERT insider threat database. For more information about the CERT Program's insider threat work, see http://www.cert.org/insider_threat/. 

This article focuses on cases in which the malicious insider was employed by a trusted business partner of the victim organization. We first define the concept of trusted business partner (TBP) and then describe case scenarios in which a TBP has become an insider threat. These case scenarios concentrate on presenting the who, what, why, and how of the illicit activity. Finally, we provide recommendations that may be useful in countering these threats

Cite This SEI Report

Lewellen, T., Moore, A., Cappelli, D., Trzeciak, R., Spooner, D., & Weiland, R. (2012, October 1). Spotlight On: Insider Threat from Trusted Business Partners Version 2: Updated and Revised. Retrieved September 17, 2026, from https://www.sei.cmu.edu/library/spotlight-on-insider-threat-from-trusted-business-partners-version-2-updated-and-revised/.

@techreport{lewellen_2012,
author={Lewellen, Todd and Moore, Andrew and Cappelli, Dawn and Trzeciak, Randall and Spooner, Derrick and Weiland, Robert},
title={Spotlight On: Insider Threat from Trusted Business Partners Version 2: Updated and Revised},
month={Oct},
year={2012},
institution={Software Engineering Institute, Carnegie Mellon University},
url={https://www.sei.cmu.edu/library/spotlight-on-insider-threat-from-trusted-business-partners-version-2-updated-and-revised/},
note={Accessed: 2026-Sep-17}
}

Lewellen, Todd, Andrew Moore, Dawn Cappelli, Randall Trzeciak, Derrick Spooner, and Robert Weiland. "Spotlight On: Insider Threat from Trusted Business Partners Version 2: Updated and Revised." Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, October 1, 2012. https://www.sei.cmu.edu/library/spotlight-on-insider-threat-from-trusted-business-partners-version-2-updated-and-revised/.

T. Lewellen, A. Moore, D. Cappelli, R. Trzeciak, D. Spooner, and R. Weiland, "Spotlight On: Insider Threat from Trusted Business Partners Version 2: Updated and Revised," Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, 1-Oct-2012 [Online]. Available: https://www.sei.cmu.edu/library/spotlight-on-insider-threat-from-trusted-business-partners-version-2-updated-and-revised/. [Accessed: 17-Sep-2026].

Lewellen, Todd, Andrew Moore, Dawn Cappelli, Randall Trzeciak, Derrick Spooner, and Robert Weiland. "Spotlight On: Insider Threat from Trusted Business Partners Version 2: Updated and Revised." Software Engineering Institute, Carnegie Mellon University, Software Engineering Institute, 1 Oct. 2012. https://www.sei.cmu.edu/library/spotlight-on-insider-threat-from-trusted-business-partners-version-2-updated-and-revised/. Accessed 17 Sep. 2026.

Lewellen, Todd; Moore, Andrew; Cappelli, Dawn; Trzeciak, Randall; Spooner, Derrick; & Weiland, Robert. Spotlight On: Insider Threat from Trusted Business Partners Version 2: Updated and Revised. Software Engineering Institute. 2012. https://www.sei.cmu.edu/library/spotlight-on-insider-threat-from-trusted-business-partners-version-2-updated-and-revised/